{"cves":[{"id":"CVE-2004-0941","published":"2005-02-09T05:00:00","updated_at":"2025-07-17T16:34:08.912939+00:00","description":"\nMultiple buffer overflows in the gd graphics library (libgd) 2.0.21 and\nearlier may allow remote attackers to execute arbitrary code via malformed\nimage files that trigger the overflows due to improper calls to the\ngdMalloc function, a different set of vulnerabilities than CVE-2004-0990.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-25-1","https://ubuntu.com/security/notices/USN-33-1","https://www.cve.org/CVERecord?id=CVE-2004-0941"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"libgd","source":"https://ubuntu.com/security/cve?package=libgd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libgd","debian":"https://tracker.debian.org/pkg/libgd","statuses":[{"release_codename":"dapper","status":"released","description":"1.8.4.debian-1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.8.4.debian-1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.8.4.debian-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libgd2","source":"https://ubuntu.com/security/cve?package=libgd2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libgd2","debian":"https://tracker.debian.org/pkg/libgd2","statuses":[{"release_codename":"dapper","status":"released","description":"2.0.33-2ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.33-4ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.34~rc1-2ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-25-1","USN-33-1"],"notices":[{"id":"USN-25-1","title":"libgd2 vulnerability","summary":"libgd2 vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2004-11-16T05:59:06","description":"CAN-2004-0990 described several more buffer overflows which had been\ndiscovered in libgd2's PNG handling functions. However, it was\ndetermined that the update from USN-11-1 was not sufficient to prevent\nevery possible attack, so another update is required.\n\nIf an attacker tricked a user into loading a malicious PNG image, they\ncould leverage this into executing arbitrary code in the context of\nthe user opening image. Most importantly, this library is commonly\nused in PHP. One possible target would be a PHP driven photo website\nthat lets users upload images. Therefore this vulnerability might lead\nto privilege escalation to a web server's privileges.","is_hidden":false,"release_packages":{"warty":[{"name":"libgd2-xpm","version":"","is_source":false,"source_link":"","version_link":""},{"name":"libgd2-noxpm","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0941"]},{"id":"USN-33-1","title":"libgd vulnerabilities","summary":"libgd vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2004-11-30T07:00:51","description":"CAN-2004-0990 described several buffer overflows which had been\ndiscovered in libgd's PNG handling functions. Another update is\nrequired because the update from USN-21-1 was not sufficient to\nprevent every possible attack.\n\nIf an attacker tricks a user into loading a malicious PNG or XPM\nimage, they could leverage this into executing arbitrary code in the\ncontext of the user opening image.\n\nThis vulnerability might lead to privilege escalation in customized\nsystems that use server applications which link libgd. However, Warty\ndoes not ship such server applications (PHP in Warty uses libgd2 which\nwas already fixed in USN-25-1).","is_hidden":false,"release_packages":{"warty":[{"name":"libgd1-xpm","version":"","is_source":false,"source_link":"","version_link":""},{"name":"libgd1-noxpm","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0941"]}]},{"id":"CVE-2004-0940","published":"2005-02-09T05:00:00","updated_at":"2025-07-17T16:34:08.912939+00:00","description":"\nBuffer overflow in the get_tag function in mod_include for Apache 1.3.x to\n1.3.32 allows local users who can create SSI documents to execute arbitrary\ncode as the apache user via SSI (XSSI) documents that trigger a length\ncalculation error.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0940"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"apache","source":"https://ubuntu.com/security/cve?package=apache","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache","debian":"https://tracker.debian.org/pkg/apache","statuses":[{"release_codename":"dapper","status":"released","description":"1.3.34-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.3.34-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.3.34-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-0233","published":"2005-02-08T05:00:00","updated_at":"2025-07-17T16:34:55.375827+00:00","description":"\nThe International Domain Name (IDN) support in Firefox 1.0, Camino .8.5,\nand Mozilla before 1.7.6 allows remote attackers to spoof domain names\nusing punycode encoded domain names that are decoded in URLs and SSL\ncertificates in a way that uses homograph characters from other character\nsets, which facilitates phishing attacks.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-149-3","https://www.cve.org/CVERecord?id=CVE-2005-0233"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mozilla","source":"https://ubuntu.com/security/cve?package=mozilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla","debian":"https://tracker.debian.org/pkg/mozilla","statuses":[{"release_codename":"dapper","status":"released","description":"1.7.12-1.1ubuntu2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.7.12-1.1ubuntu2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-149-3"],"notices":[{"id":"USN-149-3","title":"Ubuntu 4.10 update for Firefox vulnerabilities","summary":"Ubuntu 4.10 update for Firefox vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-07-28T19:16:31","description":"USN-149-1 fixed some vulnerabilities in the Ubuntu 5.04 (Hoary\nHedgehog) version of Firefox. The version shipped with Ubuntu 4.10\n(Warty Warthog) is also vulnerable to these flaws, so it needs to be\nupgraded as well. Please see\n\n http://www.ubuntulinux.org/support/documentation/usn/usn-149-1\n\nfor the original advisory.\n\nThis update also fixes several older vulnerabilities; Some of them\ncould be exploited to execute arbitrary code with full user privileges\nif the user visited a malicious web site. (MFSA-2005-01 to\nMFSA-2005-44; please see the following web site for details:\nhttp://www.mozilla.org/projects/security/known-vulnerabilities.html)","is_hidden":false,"release_packages":{"warty":[{"name":"mozilla-firefox","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-es","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-ja","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-ca","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-uk","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-de","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-nb","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-it","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-tr","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-fr","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-pl","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-1156","CVE-2004-1381","CVE-2005-0141","CVE-2005-0142","CVE-2005-0143","CVE-2005-0144","CVE-2005-0145","CVE-2005-0146","CVE-2005-0147","CVE-2005-0150","CVE-2005-0230","CVE-2005-0231","CVE-2005-0232","CVE-2005-0233","CVE-2005-0255","CVE-2005-0399","CVE-2005-0401","CVE-2005-0402","CVE-2005-0578","CVE-2005-0584","CVE-2005-0585","CVE-2005-0586","CVE-2005-0587","CVE-2005-0588","CVE-2005-0589","CVE-2005-0590","CVE-2005-0591","CVE-2005-0592","CVE-2005-0593","CVE-2005-0752","CVE-2005-0989","CVE-2005-1153","CVE-2005-1154","CVE-2005-1155","CVE-2005-1156","CVE-2005-1157","CVE-2005-1158","CVE-2005-1159","CVE-2005-1160","CVE-2005-1531","CVE-2005-1532","CVE-2005-1937","CVE-2005-2260","CVE-2005-2261","CVE-2005-2262","CVE-2005-2263","CVE-2005-2264","CVE-2005-2265","CVE-2005-2266","CVE-2005-2267","CVE-2005-2268","CVE-2005-2269","CVE-2005-2270"]}]},{"id":"CVE-2005-0231","published":"2005-02-07T05:00:00","updated_at":"2025-07-17T16:34:55.375827+00:00","description":"\nFirefox 1.0 does not invoke the Javascript Security Manager when a user\ndrags a javascript: or data: URL to a tab, which allows remote attackers to\nbypass the security model, aka \"firetabbing.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-149-3","https://www.cve.org/CVERecord?id=CVE-2005-0231"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.0.0.6+0dfsg-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.0.0.6+1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox-granparadiso","source":"https://ubuntu.com/security/cve?package=firefox-granparadiso","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-granparadiso","debian":"https://tracker.debian.org/pkg/firefox-granparadiso","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lightning-sunbird","source":"https://ubuntu.com/security/cve?package=lightning-sunbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lightning-sunbird","debian":"https://tracker.debian.org/pkg/lightning-sunbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozilla","source":"https://ubuntu.com/security/cve?package=mozilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla","debian":"https://tracker.debian.org/pkg/mozilla","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-149-3"],"notices":[{"id":"USN-149-3","title":"Ubuntu 4.10 update for Firefox vulnerabilities","summary":"Ubuntu 4.10 update for Firefox vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-07-28T19:16:31","description":"USN-149-1 fixed some vulnerabilities in the Ubuntu 5.04 (Hoary\nHedgehog) version of Firefox. The version shipped with Ubuntu 4.10\n(Warty Warthog) is also vulnerable to these flaws, so it needs to be\nupgraded as well. Please see\n\n http://www.ubuntulinux.org/support/documentation/usn/usn-149-1\n\nfor the original advisory.\n\nThis update also fixes several older vulnerabilities; Some of them\ncould be exploited to execute arbitrary code with full user privileges\nif the user visited a malicious web site. (MFSA-2005-01 to\nMFSA-2005-44; please see the following web site for details:\nhttp://www.mozilla.org/projects/security/known-vulnerabilities.html)","is_hidden":false,"release_packages":{"warty":[{"name":"mozilla-firefox","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-es","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-ja","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-ca","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-uk","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-de","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-nb","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-it","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-tr","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-fr","version":"","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-firefox-locale-pl","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-1156","CVE-2004-1381","CVE-2005-0141","CVE-2005-0142","CVE-2005-0143","CVE-2005-0144","CVE-2005-0145","CVE-2005-0146","CVE-2005-0147","CVE-2005-0150","CVE-2005-0230","CVE-2005-0231","CVE-2005-0232","CVE-2005-0233","CVE-2005-0255","CVE-2005-0399","CVE-2005-0401","CVE-2005-0402","CVE-2005-0578","CVE-2005-0584","CVE-2005-0585","CVE-2005-0586","CVE-2005-0587","CVE-2005-0588","CVE-2005-0589","CVE-2005-0590","CVE-2005-0591","CVE-2005-0592","CVE-2005-0593","CVE-2005-0752","CVE-2005-0989","CVE-2005-1153","CVE-2005-1154","CVE-2005-1155","CVE-2005-1156","CVE-2005-1157","CVE-2005-1158","CVE-2005-1159","CVE-2005-1160","CVE-2005-1531","CVE-2005-1532","CVE-2005-1937","CVE-2005-2260","CVE-2005-2261","CVE-2005-2262","CVE-2005-2263","CVE-2005-2264","CVE-2005-2265","CVE-2005-2266","CVE-2005-2267","CVE-2005-2268","CVE-2005-2269","CVE-2005-2270"]}]},{"id":"CVE-2005-0175","published":"2005-02-07T05:00:00","updated_at":"2025-07-17T16:34:50.252240+00:00","description":"\nSquid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via\nan HTTP response splitting attack.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-77-1","https://www.cve.org/CVERecord?id=CVE-2005-0175"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"squid","source":"https://ubuntu.com/security/cve?package=squid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squid","debian":"https://tracker.debian.org/pkg/squid","statuses":[{"release_codename":"dapper","status":"released","description":"2.5.12-4ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.1-3ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.5-4ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-77-1"],"notices":[{"id":"USN-77-1","title":"Squid vulnerabilities","summary":"Squid vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-02-08T01:33:45","description":"A possible authentication bypass was discovered in the LDAP\nauthentication backend. LDAP ignores leading and trailing whitespace\nin search filters. This could possibly be abused to bypass explicit\naccess controls or confuse accounting when using several variants of\nthe login name. (CAN-2005-0173)\n\nPrevious Squid versions were not strict enough while parsing HTTP\nrequests and responses. Various violations of the HTTP protocol, such\nas multiple Content-Length header lines, invalid \"Carriage Return\"\ncharacters, and HTTP header names containing whitespace, led to cache\npollution and could possibly be exploited to deliver wrong content to\nclients. (CAN-2005-0174)\n\nSquid was susceptible to a cache poisoning attack called \"HTTP\nresponse splitting\", where false replies are injected in the HTTP\nstream. This allowed malicious web servers to forge wrong cache\ncontent for arbitrary web sites, which was then delivered to Squid\nclients. (CAN-2005-0175)\n\nThe FSC Vulnerability Research Team discovered a buffer overflow in\nthe WCCP handling protocol. By sending an overly large WCCP packet, a\nremote attacker could crash the Squid server, and possibly even\nexecute arbitrary code with the privileges of the \"proxy\" user.\n(CAN-2005-0211)","is_hidden":false,"release_packages":{"warty":[{"name":"squid","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-0173","CVE-2005-0174","CVE-2005-0175","CVE-2005-0211"]}]},{"id":"CVE-2005-0174","published":"2005-02-07T05:00:00","updated_at":"2025-07-17T16:34:50.252240+00:00","description":"\nSquid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or\nconduct certain attacks via headers that do not follow the HTTP\nspecification, including (1) multiple Content-Length headers, (2) carriage\nreturn (CR) characters that are not part of a CRLF pair, and (3) header\nnames containing whitespace characters.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-77-1","https://www.cve.org/CVERecord?id=CVE-2005-0174"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"squid","source":"https://ubuntu.com/security/cve?package=squid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squid","debian":"https://tracker.debian.org/pkg/squid","statuses":[{"release_codename":"dapper","status":"released","description":"2.5.12-4ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.1-3ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.5-4ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-77-1"],"notices":[{"id":"USN-77-1","title":"Squid vulnerabilities","summary":"Squid vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-02-08T01:33:45","description":"A possible authentication bypass was discovered in the LDAP\nauthentication backend. LDAP ignores leading and trailing whitespace\nin search filters. This could possibly be abused to bypass explicit\naccess controls or confuse accounting when using several variants of\nthe login name. (CAN-2005-0173)\n\nPrevious Squid versions were not strict enough while parsing HTTP\nrequests and responses. Various violations of the HTTP protocol, such\nas multiple Content-Length header lines, invalid \"Carriage Return\"\ncharacters, and HTTP header names containing whitespace, led to cache\npollution and could possibly be exploited to deliver wrong content to\nclients. (CAN-2005-0174)\n\nSquid was susceptible to a cache poisoning attack called \"HTTP\nresponse splitting\", where false replies are injected in the HTTP\nstream. This allowed malicious web servers to forge wrong cache\ncontent for arbitrary web sites, which was then delivered to Squid\nclients. (CAN-2005-0175)\n\nThe FSC Vulnerability Research Team discovered a buffer overflow in\nthe WCCP handling protocol. By sending an overly large WCCP packet, a\nremote attacker could crash the Squid server, and possibly even\nexecute arbitrary code with the privileges of the \"proxy\" user.\n(CAN-2005-0211)","is_hidden":false,"release_packages":{"warty":[{"name":"squid","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-0173","CVE-2005-0174","CVE-2005-0175","CVE-2005-0211"]}]},{"id":"CVE-2005-0156","published":"2005-02-07T05:00:00","updated_at":"2025-07-17T16:34:48.773814+00:00","description":"\nBuffer overflow in the PerlIO implementation in Perl 5.8.0, when installed\nwith setuid support (sperl), allows local users to execute arbitrary code\nby setting the PERLIO_DEBUG variable and executing a Perl script whose full\npathname contains a long directory tree.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-72-1","https://www.cve.org/CVERecord?id=CVE-2005-0156"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"perl","source":"https://ubuntu.com/security/cve?package=perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=perl","debian":"https://tracker.debian.org/pkg/perl","statuses":[{"release_codename":"dapper","status":"released","description":"5.8.7-10ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"5.8.7-10ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"5.8.7-10ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-72-1"],"notices":[{"id":"USN-72-1","title":"Perl vulnerabilities","summary":"Perl vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-02-02T22:57:49","description":"Two exploitable vulnerabilities involving setuid-enabled perl scripts\nhave been discovered. The package \"perl-suid\" provides a wrapper\naround perl which allows to use setuid-root perl scripts, i.e.\nuser-callable Perl scripts which have full root privileges.\n\nPrevious versions allowed users to overwrite arbitrary files by\nsetting the PERLIO_DEBUG environment variable and calling an arbitrary\nsetuid-root perl script. The file that PERLIO_DEBUG points to was then\noverwritten by Perl debug messages. This did not allow precise control\nover the file content, but could destroy important data. PERLIO_DEBUG\nis now ignored for setuid scripts. (CAN-2005-0155)\n\nIn addition, calling a setuid-root perl script with a very long path\ncaused a buffer overflow if PERLIO_DEBUG was set. This buffer overflow\ncould be exploited to execute arbitrary files with full root\nprivileges. (CAN-2005-0156)","is_hidden":false,"release_packages":{"warty":[{"name":"perl","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-0155","CVE-2005-0156"]}]},{"id":"CVE-2005-0100","published":"2005-02-07T05:00:00","updated_at":"2025-07-17T16:34:43.979966+00:00","description":"\nFormat string vulnerability in the movemail utility in (1) Emacs 20.x,\n21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows\nremote malicious POP3 servers to execute arbitrary code via crafted\npackets.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-76-1","https://www.cve.org/CVERecord?id=CVE-2005-0100"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"emacs21","source":"https://ubuntu.com/security/cve?package=emacs21","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=emacs21","debian":"https://tracker.debian.org/pkg/emacs21","statuses":[{"release_codename":"dapper","status":"released","description":"21.4a-3ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"21.4a-6ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"21.4a+1-2ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xemacs21","source":"https://ubuntu.com/security/cve?package=xemacs21","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xemacs21","debian":"https://tracker.debian.org/pkg/xemacs21","statuses":[{"release_codename":"dapper","status":"released","description":"21.4.18-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"21.4.18-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"21.4.18-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-76-1"],"notices":[{"id":"USN-76-1","title":"Emacs vulnerability","summary":"Emacs vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-02-07T20:58:32","description":"Max Vozeler discovered a format string vulnerability in the \"movemail\"\nutility of Emacs. By sending specially crafted packets, a malicious\nPOP3 server could cause a buffer overflow, which could have been\nexploited to execute arbitrary code with the privileges of the user\nand the \"mail\" group (since \"movemail\" is installed as \"setgid mail\").","is_hidden":false,"release_packages":{"warty":[{"name":"emacs21-bin-common","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-0100"]}]},{"id":"CVE-2005-0152","published":"2005-02-02T05:00:00","updated_at":"2025-07-17T16:34:48.773814+00:00","description":"\nPHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote\nattackers to execute arbitrary code via \"URL manipulation.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-0152"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"squirrelmail","source":"https://ubuntu.com/security/cve?package=squirrelmail","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squirrelmail","debian":"https://tracker.debian.org/pkg/squirrelmail","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-0245","published":"2005-02-01T05:00:00","updated_at":"2025-07-17T16:34:55.375827+00:00","description":"\nBuffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow\nattackers to execute arbitrary code via a large number of arguments to a\nrefcursor function (gram.y), which leads to a heap-based buffer overflow, a\ndifferent vulnerability than CVE-2005-0247.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-79-1","https://www.cve.org/CVERecord?id=CVE-2005-0245"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"postgresql","source":"https://ubuntu.com/security/cve?package=postgresql","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql","debian":"https://tracker.debian.org/pkg/postgresql","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-79-1"],"notices":[{"id":"USN-79-1","title":"PostgreSQL vulnerabilities","summary":"PostgreSQL vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2005-02-11T00:16:27","description":"The execution of custom PostgreSQL functions can be restricted with\nthe EXECUTE privilege. However, previous versions did not check this\nprivilege when executing a function which was part of an aggregate.\nAs a result, any database user could circumvent the EXECUTE restriction of\nfunctions with a particular (but very common) parameter structure by\ncreating an aggregate wrapper around the function. (CAN-2005-0244)\n\nSeveral buffer overflows have been discovered in the SQL parser. These\ncould be exploited by any database user to crash the PostgreSQL server\nor execute arbitrary code with the privileges of the server.\n(CAN-2005-0245, CAN-2005-0247)\n\nFinally, this update fixes a Denial of Service vulnerability of the\ncontributed \"intagg\" module. By constructing specially crafted arrays,\na database user was able to corrupt and crash the PostgreSQL server.\n(CAN-2005-0246). Please note that this module is part of the\n\"postgresql-contrib\" package, which is not officially supported by\nUbuntu.","is_hidden":false,"release_packages":{"warty":[{"name":"postgresql","version":"","is_source":false,"source_link":"","version_link":""},{"name":"postgresql-contrib","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2005-0246","CVE-2005-0245","CVE-2005-0247","CVE-2005-0244"]}]},{"id":"CVE-2005-0101","published":"2005-02-01T05:00:00","updated_at":"2025-07-17T16:34:43.979966+00:00","description":"\nBuffer overflow in the socket_getline function in Newspost 2.1.1 and\nearlier allows remote malicious NNTP servers to execute arbitrary code via\na long string without a newline character.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-0101"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"newspost","source":"https://ubuntu.com/security/cve?package=newspost","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=newspost","debian":"https://tracker.debian.org/pkg/newspost","statuses":[{"release_codename":"dapper","status":"released","description":"2.1.1-4","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.1.1-4","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.1.1-4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-0104","published":"2005-01-29T05:00:00","updated_at":"2025-07-17T16:34:45.668196+00:00","description":"\nCross-site scripting (XSS) vulnerability in webmail.php in SquirrelMail\nbefore 1.4.4 allows remote attackers to inject arbitrary web script or HTML\nvia certain integer variables.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-0104"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"squirrelmail","source":"https://ubuntu.com/security/cve?package=squirrelmail","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squirrelmail","debian":"https://tracker.debian.org/pkg/squirrelmail","statuses":[{"release_codename":"dapper","status":"released","description":"1.4.6-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.4.8-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.4.9a-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2005-0075","published":"2005-01-29T05:00:00","updated_at":"2025-07-17T16:34:42.165154+00:00","description":"\nprefs.php in SquirrelMail before 1.4.4, with register_globals enabled,\nallows remote attackers to inject local code into the SquirrelMail code via\ncustom preference handlers.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2005-0075"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"squirrelmail","source":"https://ubuntu.com/security/cve?package=squirrelmail","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squirrelmail","debian":"https://tracker.debian.org/pkg/squirrelmail","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0930","published":"2005-01-27T05:00:00","updated_at":"2025-07-17T16:34:08.912939+00:00","description":"\nThe ms_fnmatch function in Samba 3.0.4 and 3.0.7 and possibly other\nversions allows remote authenticated users to cause a denial of service\n(CPU consumption) via a SAMBA request that contains multiple * (wildcard)\ncharacters.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-22-1","https://www.cve.org/CVERecord?id=CVE-2004-0930"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"samba","source":"https://ubuntu.com/security/cve?package=samba","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=samba","debian":"https://tracker.debian.org/pkg/samba","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-22-1"],"notices":[{"id":"USN-22-1","title":"samba vulnerability","summary":"samba vulnerability","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2004-11-10T09:13:10","description":"Karol Wiesek discovered a Denial of Service vulnerability in samba. A\nflaw in the input validation routines used to match filename strings\ncontaining wildcard characters may allow a remote user to consume more\nthan normal amounts of CPU resources, thus impacting the performance\nand response of the server. In some circumstances the server can\nbecome entirely unresponsive.","is_hidden":false,"release_packages":{"warty":[{"name":"samba","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0930"]}]},{"id":"CVE-2004-0923","published":"2005-01-27T05:00:00","updated_at":"2025-07-17T16:34:08.912939+00:00","description":"\nCUPS 1.1.20 and earlier records authentication information for a device URI\nin the error_log file, which allows local users to obtain user names and\npasswords.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0923"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"cupsys","source":"https://ubuntu.com/security/cve?package=cupsys","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cupsys","debian":"https://tracker.debian.org/pkg/cupsys","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"samba","source":"https://ubuntu.com/security/cve?package=samba","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=samba","debian":"https://tracker.debian.org/pkg/samba","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2004-0918","published":"2005-01-27T05:00:00","updated_at":"2025-07-17T16:34:07.516667+00:00","description":"\nThe asn_parse_header function (asn1.c) in the SNMP module for Squid Web\nProxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of\nservice (server restart) via certain SNMP packets with negative length\nfields that trigger a memory allocation error.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-19-1","https://www.cve.org/CVERecord?id=CVE-2004-0918"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"squid","source":"https://ubuntu.com/security/cve?package=squid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squid","debian":"https://tracker.debian.org/pkg/squid","statuses":[{"release_codename":"dapper","status":"released","description":"2.5.12-4ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.1-3ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"2.6.5-4ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-19-1"],"notices":[{"id":"USN-19-1","title":"squid vulnerabilities","summary":"squid vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2004-11-07T03:51:42","description":"Recently, two Denial of Service vulnerabilities have been discovered\nin squid, a WWW proxy cache. Insufficient input validation in the NTLM\nauthentication handler allowed a remote attacker to crash the service\nby sending a specially crafted NTLMSSP packet. Likewise, due to an\ninsufficient validation of ASN.1 headers, a remote attacker could\nrestart the server (causing all open connections to be dropped) by\nsending certain SNMP packets with negative length fields.","is_hidden":false,"release_packages":{"warty":[{"name":"squid","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0832","CVE-2004-0918"]}]},{"id":"CVE-2004-0891","published":"2005-01-27T05:00:00","updated_at":"2025-07-17T16:34:07.516667+00:00","description":"\nBuffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows\nremote attackers to cause a denial of service (application crash) and\npossibly execute arbitrary code via an \"unexpected sequence of MSNSLP\nmessages\" that results in an unbounded copy operation that writes to the\nwrong buffer.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-8-1","https://www.cve.org/CVERecord?id=CVE-2004-0891"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"gaim","source":"https://ubuntu.com/security/cve?package=gaim","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gaim","debian":"https://tracker.debian.org/pkg/gaim","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0+1.5.1cvs20051015-1ubuntu10","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.0+1.5.1cvs20051015-1ubuntu10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.5.0+1.5.1cvs20051015-1ubuntu10","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8-1"],"notices":[{"id":"USN-8-1","title":"gaim vulnerabilities","summary":"gaim vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2004-10-27T09:53:22","description":"A buffer overflow and two remote crashes were recently discovered in\ngaim's MSN protocol handler. An attacker could potentially execute\narbitrary code with the user's privileges by crafting and sending a\nparticular MSN message.","is_hidden":false,"release_packages":{"warty":[{"name":"gaim","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0891"]}]},{"id":"CVE-2004-0889","published":"2005-01-27T05:00:00","updated_at":"2025-07-17T16:34:07.516667+00:00","description":"\nMultiple integer overflows in xpdf 3.0, and other packages that use xpdf\ncode such as CUPS, allow remote attackers to cause a denial of service\n(crash) and possibly execute arbitrary code, a different set of\nvulnerabilities than those identified by CVE-2004-0888.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2-1","https://ubuntu.com/security/notices/USN-14-1","https://www.cve.org/CVERecord?id=CVE-2004-0889"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"kdegraphics","source":"https://ubuntu.com/security/cve?package=kdegraphics","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kdegraphics","debian":"https://tracker.debian.org/pkg/kdegraphics","statuses":[{"release_codename":"dapper","status":"released","description":"3.5.2-0ubuntu6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.5.2-0ubuntu6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.5.2-0ubuntu6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"koffice","source":"https://ubuntu.com/security/cve?package=koffice","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=koffice","debian":"https://tracker.debian.org/pkg/koffice","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0-0ubuntu9.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.2-0ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.6.2-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xpdf","source":"https://ubuntu.com/security/cve?package=xpdf","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xpdf","debian":"https://tracker.debian.org/pkg/xpdf","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.01-9ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.01-9ubuntu3","component":null,"pocket":"security"},{"release_codename":"dapper","status":"released","description":"3.01-7ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-14-1","USN-2-1"],"notices":[{"id":"USN-14-1","title":"xpdf vulnerabilities","summary":"xpdf vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2004-11-02T02:33:42","description":"Markus Meissner discovered even more integer overflow vulnerabilities\nin xpdf, a viewer for PDF files. These integer overflows can\neventually lead to buffer overflows.\n\nThe Common UNIX Printing System (CUPS) uses the same code to print PDF\nfiles; tetex-bin uses the code to generate PDF output and process\nincluded PDF files. In any case, these vulnerabilities could be\nexploited by an attacker providing a specially crafted PDF file which,\nwhen processed by CUPS, xpdf, or pdflatex, could result in abnormal\nprogram termination or the execution of program code supplied by the\nattacker.\n\nIn the case of CUPS, this bug could be exploited to gain the privileges of\nthe CUPS print server (by default, user cupsys).\n\nIn the cases of xpdf and pdflatex, this bug could be exploited to gain\nthe privileges of the user invoking the program.","is_hidden":false,"release_packages":{"warty":[{"name":"cupsys","version":"","is_source":false,"source_link":"","version_link":""},{"name":"xpdf-utils","version":"","is_source":false,"source_link":"","version_link":""},{"name":"tetex-bin","version":"","is_source":false,"source_link":"","version_link":""},{"name":"xpdf-reader","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0888","CVE-2004-0889"]},{"id":"USN-2-1","title":"xpdf vulnerabilities","summary":"xpdf vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2004-10-23T02:11:46","description":"Chris Evans discovered several integer overflow vulnerabilities in xpdf, a\nviewer for PDF files. The Common UNIX Printing System (CUPS) also uses the\nsame code to print PDF files. In either case, these vulnerabilities could\nbe exploited by an attacker by providing a specially crafted PDF file which,\nwhen processed by CUPS or xpdf, could result in abnormal program termination\nor the execution of program code supplied by the attacker.\n\nIn the case of CUPS, this bug could be exploited to gain the privileges of\nthe CUPS print server (by default, user cupsys).\n\nIn the case of xpdf, this bug could be exploited to gain the privileges of\nthe user invoking xpdf.","is_hidden":false,"release_packages":{"warty":[{"name":"cupsys","version":"","is_source":false,"source_link":"","version_link":""},{"name":"xpdf-utils","version":"","is_source":false,"source_link":"","version_link":""},{"name":"xpdf-reader","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0889"]}]},{"id":"CVE-2004-0888","published":"2005-01-27T05:00:00","updated_at":"2025-07-17T16:34:07.516667+00:00","description":"\nMultiple integer overflows in xpdf 2.0 and 3.0, and other packages that use\nxpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to\ncause a denial of service (crash) and possibly execute arbitrary code, a\ndifferent set of vulnerabilities than those identified by CVE-2004-0889.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-9-1","https://ubuntu.com/security/notices/USN-14-1","https://www.cve.org/CVERecord?id=CVE-2004-0888"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"cupsys","source":"https://ubuntu.com/security/cve?package=cupsys","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cupsys","debian":"https://tracker.debian.org/pkg/cupsys","statuses":[{"release_codename":"edgy","status":"released","description":"1.2.0-0ubuntu5","component":null,"pocket":"security"},{"release_codename":"dapper","status":"released","description":"1.2.0-0ubuntu5","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.2.0-0ubuntu5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"gpdf","source":"https://ubuntu.com/security/cve?package=gpdf","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpdf","debian":"https://tracker.debian.org/pkg/gpdf","statuses":[{"release_codename":"dapper","status":"released","description":"2.10.0-2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.10.0-2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"kdegraphics","source":"https://ubuntu.com/security/cve?package=kdegraphics","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kdegraphics","debian":"https://tracker.debian.org/pkg/kdegraphics","statuses":[{"release_codename":"dapper","status":"released","description":"3.5.2-0ubuntu6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.5.2-0ubuntu6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.5.2-0ubuntu6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"koffice","source":"https://ubuntu.com/security/cve?package=koffice","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=koffice","debian":"https://tracker.debian.org/pkg/koffice","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0-0ubuntu9.2","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.2-0ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.6.2-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"pdftohtml","source":"https://ubuntu.com/security/cve?package=pdftohtml","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pdftohtml","debian":"https://tracker.debian.org/pkg/pdftohtml","statuses":[{"release_codename":"dapper","status":"released","description":"0.36-13","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.36-13","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.36-13","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tetex-bin","source":"https://ubuntu.com/security/cve?package=tetex-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tetex-bin","debian":"https://tracker.debian.org/pkg/tetex-bin","statuses":[{"release_codename":"dapper","status":"released","description":"3.0-13ubuntu6","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.0-13ubuntu6","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.0-13ubuntu6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-14-1","USN-9-1"],"notices":[{"id":"USN-14-1","title":"xpdf vulnerabilities","summary":"xpdf vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2004-11-02T02:33:42","description":"Markus Meissner discovered even more integer overflow vulnerabilities\nin xpdf, a viewer for PDF files. These integer overflows can\neventually lead to buffer overflows.\n\nThe Common UNIX Printing System (CUPS) uses the same code to print PDF\nfiles; tetex-bin uses the code to generate PDF output and process\nincluded PDF files. In any case, these vulnerabilities could be\nexploited by an attacker providing a specially crafted PDF file which,\nwhen processed by CUPS, xpdf, or pdflatex, could result in abnormal\nprogram termination or the execution of program code supplied by the\nattacker.\n\nIn the case of CUPS, this bug could be exploited to gain the privileges of\nthe CUPS print server (by default, user cupsys).\n\nIn the cases of xpdf and pdflatex, this bug could be exploited to gain\nthe privileges of the user invoking the program.","is_hidden":false,"release_packages":{"warty":[{"name":"cupsys","version":"","is_source":false,"source_link":"","version_link":""},{"name":"xpdf-utils","version":"","is_source":false,"source_link":"","version_link":""},{"name":"tetex-bin","version":"","is_source":false,"source_link":"","version_link":""},{"name":"xpdf-reader","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0888","CVE-2004-0889"]},{"id":"USN-9-1","title":"tetex-bin vulnerabilities","summary":"tetex-bin vulnerabilities","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2004-10-28T15:08:47","description":"Chris Evans and Marcus Meissner recently discovered several integer\noverflow vulnerabilities in xpdf, a viewer for PDF files. Because\ntetex-bin contains xpdf code, it is also affected. These\nvulnerabilities could be exploited by an attacker providing a\nspecially crafted TeX, LaTeX, or PDF file. Processing such a file with\npdflatex could result in abnormal program termination or the execution\nof program code supplied by the attacker.\n\nThis bug could be exploited to gain the privileges of the user\ninvoking pdflatex.","is_hidden":false,"release_packages":{"warty":[{"name":"tetex-bin","version":"","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2004-0888","CVE-2004-0888"]}]},{"id":"CVE-2004-0887","published":"2005-01-27T05:00:00","updated_at":"2025-07-17T16:34:06.161694+00:00","description":"\nSUSE Linux Enterprise Server 9 on the S/390 platform does not properly\nhandle a certain privileged instruction, which allows local users to gain\nroot privileges.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2004-0887"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-29.58","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.17","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.17","debian":"https://tracker.debian.org/pkg/linux-source-2.6.17","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"2.6.17.1-12.40","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":78880,"limit":20,"total_results":79316}